CWE-20
12,724 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CVEs (12,724)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Opera before 10.63 allows remote attackers to cause a denial of service (application crash) via a Flash movie with a transparent Window Mode (aka wmode) property, which is not properly handled during navigation away from...Show more |
Opera before 10.63 allows user-assisted remote web servers to cause a denial of service (application crash) by sending a redirect during the saving of a file. |
Opera before 10.63 does not ensure that the portion of a URL shown in the Address Bar contains the beginning of the URL, which allows remote attackers to spoof URLs by changing a window's size. |
2Google Opensuse2Chrome OpensuseApr 29, 2026 Oct 21, 2010 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "stale elements." |
3Debian GoogleOpensuse3Chrome Debian LinuxOpensuseApr 29, 2026 Oct 21, 2010 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image. |
Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors. |
Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a craf...Show more |
Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document. |
bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. |
The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed...Show more |
FTPServer.py in pyftpdlib before 0.2.0 allows remote attackers to cause a denial of service via a long command. |
1Realnetworks 2Realplayer Realplayer SpApr 29, 2026 Oct 19, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction with a heap buffer, wh...Show more |
1Realnetworks 2Realplayer Realplayer SpApr 29, 2026 Oct 19, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Array index error in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.0.1 allows remote attackers to execute arbitrary code via malformed sample data in a RealMedia .IVR file, related to a "malfo...Show more |
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1) does not correspond...Show more |
1Microsoft 3Excel OfficeOpen Xml File Format ConverterApr 29, 2026 Oct 13, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel...Show more |
1Microsoft 3Excel OfficeOpen Xml File Format ConverterApr 29, 2026 Oct 13, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a cr...Show more |
1Microsoft 3Excel Excel ViewerOffice Compatibility PackApr 29, 2026 Oct 13, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to e...Show more |
Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability." |
Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negati...Show more |
Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerabi...Show more |